Which of the following would BEST enable a risk practitioner to embed risk management within the organization?
Correct Answer: D
* Engaging key stakeholders in risk management practices is the best way to embed risk management within the organization. This means that the risk practitioner involves and communicates with the people who have an interest or influence in the organization's objectives, activities, and risks, such as senior management, business unit managers, employees, customers, suppliers, regulators, etc.
* Engaging key stakeholders in risk management practices helps to create a risk-aware culture, align risk management with the organization's strategy and vision, ensure the ownership and accountability of risks and controls, obtain the support and commitment for risk management initiatives, and improve the risk management performance and outcomes.
* The other options are not the best ways to embed risk management within the organization. They are either secondary or not essential for risk management.
The references for this answer are:
* Risk IT Framework, page 17
* Information Technology & Security, page 11
* Risk Scenarios Starter Pack, page 9